MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 18ebc3f3e74fc7a11f097eefd4f5864a7a49b490449dc6adf37fbe86ba279427. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 18ebc3f3e74fc7a11f097eefd4f5864a7a49b490449dc6adf37fbe86ba279427
SHA3-384 hash: d09846dfabe822a1668a9370428a6b0e483a21bda3f6c4e25dabf058a0b840357ec856e2ee4fd63ce4c0dff805e7b5d3
SHA1 hash: 0bfddbcabf96e55eb4f87106fc5cd114ff894c2f
MD5 hash: 0734d385d092fa6b27a635e843eee6ee
humanhash: august-jig-orange-nevada
File name:aws
Download: download sample
File size:2'399 bytes
First seen:2025-07-10 13:02:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxS4rx0xX9Frxuwxuj0rxZxaArxyxlhrxbx0mrx8xfzrxGxpxrxdxukrxnxA/:vlTS4liX9Flb60l7aAlQlhlV0mlKfzlN
TLSH T1F841A0F50144073CACF2EA6E31E689C8B6E196C620D29FC495FC38E5404DE4C3DA2E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=761d5b99-1a00-0000-fcd4-c089690b0000 pid=2921 /usr/bin/sudo guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924 /tmp/sample.bin guuid=761d5b99-1a00-0000-fcd4-c089690b0000 pid=2921->guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924 execve guuid=e98f239e-1a00-0000-fcd4-c0896f0b0000 pid=2927 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=e98f239e-1a00-0000-fcd4-c0896f0b0000 pid=2927 execve guuid=7f8e01a3-1a00-0000-fcd4-c089780b0000 pid=2936 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7f8e01a3-1a00-0000-fcd4-c089780b0000 pid=2936 execve guuid=497feaab-1a00-0000-fcd4-c089860b0000 pid=2950 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=497feaab-1a00-0000-fcd4-c089860b0000 pid=2950 execve guuid=7e1e93ac-1a00-0000-fcd4-c089870b0000 pid=2951 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7e1e93ac-1a00-0000-fcd4-c089870b0000 pid=2951 execve guuid=a4a40aad-1a00-0000-fcd4-c089890b0000 pid=2953 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=a4a40aad-1a00-0000-fcd4-c089890b0000 pid=2953 clone guuid=94d848ad-1a00-0000-fcd4-c0898a0b0000 pid=2954 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=94d848ad-1a00-0000-fcd4-c0898a0b0000 pid=2954 execve guuid=9db38aaf-1a00-0000-fcd4-c089900b0000 pid=2960 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=9db38aaf-1a00-0000-fcd4-c089900b0000 pid=2960 execve guuid=51dc82b6-1a00-0000-fcd4-c089930b0000 pid=2963 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=51dc82b6-1a00-0000-fcd4-c089930b0000 pid=2963 execve guuid=ab9c2db7-1a00-0000-fcd4-c089950b0000 pid=2965 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=ab9c2db7-1a00-0000-fcd4-c089950b0000 pid=2965 execve guuid=4b7a98b7-1a00-0000-fcd4-c089960b0000 pid=2966 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=4b7a98b7-1a00-0000-fcd4-c089960b0000 pid=2966 clone guuid=f0a0ccb7-1a00-0000-fcd4-c089970b0000 pid=2967 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=f0a0ccb7-1a00-0000-fcd4-c089970b0000 pid=2967 execve guuid=7d9d08bb-1a00-0000-fcd4-c089a00b0000 pid=2976 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7d9d08bb-1a00-0000-fcd4-c089a00b0000 pid=2976 execve guuid=ac489fbe-1a00-0000-fcd4-c089a10b0000 pid=2977 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=ac489fbe-1a00-0000-fcd4-c089a10b0000 pid=2977 execve guuid=4b0237bf-1a00-0000-fcd4-c089a30b0000 pid=2979 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=4b0237bf-1a00-0000-fcd4-c089a30b0000 pid=2979 execve guuid=5c0b84bf-1a00-0000-fcd4-c089a40b0000 pid=2980 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=5c0b84bf-1a00-0000-fcd4-c089a40b0000 pid=2980 clone guuid=40f2d1bf-1a00-0000-fcd4-c089a50b0000 pid=2981 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=40f2d1bf-1a00-0000-fcd4-c089a50b0000 pid=2981 execve guuid=267ef7c1-1a00-0000-fcd4-c089a90b0000 pid=2985 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=267ef7c1-1a00-0000-fcd4-c089a90b0000 pid=2985 execve guuid=c46774c4-1a00-0000-fcd4-c089af0b0000 pid=2991 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=c46774c4-1a00-0000-fcd4-c089af0b0000 pid=2991 execve guuid=c541fbc4-1a00-0000-fcd4-c089b20b0000 pid=2994 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=c541fbc4-1a00-0000-fcd4-c089b20b0000 pid=2994 execve guuid=3d7e4bc5-1a00-0000-fcd4-c089b40b0000 pid=2996 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=3d7e4bc5-1a00-0000-fcd4-c089b40b0000 pid=2996 clone guuid=546f7bc5-1a00-0000-fcd4-c089b50b0000 pid=2997 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=546f7bc5-1a00-0000-fcd4-c089b50b0000 pid=2997 execve guuid=5b15afc7-1a00-0000-fcd4-c089bd0b0000 pid=3005 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=5b15afc7-1a00-0000-fcd4-c089bd0b0000 pid=3005 execve guuid=1da4eaca-1a00-0000-fcd4-c089c50b0000 pid=3013 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=1da4eaca-1a00-0000-fcd4-c089c50b0000 pid=3013 execve guuid=fe0645cb-1a00-0000-fcd4-c089c60b0000 pid=3014 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=fe0645cb-1a00-0000-fcd4-c089c60b0000 pid=3014 execve guuid=22a4bacb-1a00-0000-fcd4-c089c80b0000 pid=3016 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=22a4bacb-1a00-0000-fcd4-c089c80b0000 pid=3016 clone guuid=2a37fccb-1a00-0000-fcd4-c089ca0b0000 pid=3018 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=2a37fccb-1a00-0000-fcd4-c089ca0b0000 pid=3018 execve guuid=137573ce-1a00-0000-fcd4-c089ce0b0000 pid=3022 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=137573ce-1a00-0000-fcd4-c089ce0b0000 pid=3022 execve guuid=ab5a63d3-1a00-0000-fcd4-c089d90b0000 pid=3033 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=ab5a63d3-1a00-0000-fcd4-c089d90b0000 pid=3033 execve guuid=83f8c2d3-1a00-0000-fcd4-c089db0b0000 pid=3035 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=83f8c2d3-1a00-0000-fcd4-c089db0b0000 pid=3035 execve guuid=851712d4-1a00-0000-fcd4-c089dc0b0000 pid=3036 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=851712d4-1a00-0000-fcd4-c089dc0b0000 pid=3036 clone guuid=55b13ad4-1a00-0000-fcd4-c089dd0b0000 pid=3037 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=55b13ad4-1a00-0000-fcd4-c089dd0b0000 pid=3037 execve guuid=f74fe6d5-1a00-0000-fcd4-c089e20b0000 pid=3042 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=f74fe6d5-1a00-0000-fcd4-c089e20b0000 pid=3042 execve guuid=9263e4d8-1a00-0000-fcd4-c089ed0b0000 pid=3053 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=9263e4d8-1a00-0000-fcd4-c089ed0b0000 pid=3053 execve guuid=5dca3ad9-1a00-0000-fcd4-c089ef0b0000 pid=3055 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=5dca3ad9-1a00-0000-fcd4-c089ef0b0000 pid=3055 execve guuid=247a7cd9-1a00-0000-fcd4-c089f10b0000 pid=3057 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=247a7cd9-1a00-0000-fcd4-c089f10b0000 pid=3057 clone guuid=d892a6d9-1a00-0000-fcd4-c089f20b0000 pid=3058 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=d892a6d9-1a00-0000-fcd4-c089f20b0000 pid=3058 execve guuid=2cb864db-1a00-0000-fcd4-c089f80b0000 pid=3064 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=2cb864db-1a00-0000-fcd4-c089f80b0000 pid=3064 execve guuid=9c2d89de-1a00-0000-fcd4-c089000c0000 pid=3072 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=9c2d89de-1a00-0000-fcd4-c089000c0000 pid=3072 execve guuid=735eeade-1a00-0000-fcd4-c089020c0000 pid=3074 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=735eeade-1a00-0000-fcd4-c089020c0000 pid=3074 execve guuid=5d9a35df-1a00-0000-fcd4-c089030c0000 pid=3075 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=5d9a35df-1a00-0000-fcd4-c089030c0000 pid=3075 clone guuid=2da1aedf-1a00-0000-fcd4-c089060c0000 pid=3078 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=2da1aedf-1a00-0000-fcd4-c089060c0000 pid=3078 execve guuid=fa1374e2-1a00-0000-fcd4-c0890e0c0000 pid=3086 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=fa1374e2-1a00-0000-fcd4-c0890e0c0000 pid=3086 execve guuid=ac38f3e6-1a00-0000-fcd4-c0891b0c0000 pid=3099 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=ac38f3e6-1a00-0000-fcd4-c0891b0c0000 pid=3099 execve guuid=287268ef-1a00-0000-fcd4-c089310c0000 pid=3121 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=287268ef-1a00-0000-fcd4-c089310c0000 pid=3121 execve guuid=aba3b8ef-1a00-0000-fcd4-c089320c0000 pid=3122 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=aba3b8ef-1a00-0000-fcd4-c089320c0000 pid=3122 clone guuid=b0aaf4ef-1a00-0000-fcd4-c089340c0000 pid=3124 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=b0aaf4ef-1a00-0000-fcd4-c089340c0000 pid=3124 execve guuid=707f46f2-1a00-0000-fcd4-c0893b0c0000 pid=3131 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=707f46f2-1a00-0000-fcd4-c0893b0c0000 pid=3131 execve guuid=6dcf6df6-1a00-0000-fcd4-c089460c0000 pid=3142 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=6dcf6df6-1a00-0000-fcd4-c089460c0000 pid=3142 execve guuid=7584b7f6-1a00-0000-fcd4-c089470c0000 pid=3143 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7584b7f6-1a00-0000-fcd4-c089470c0000 pid=3143 execve guuid=fdf00ef7-1a00-0000-fcd4-c0894a0c0000 pid=3146 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=fdf00ef7-1a00-0000-fcd4-c0894a0c0000 pid=3146 clone guuid=1fc53af7-1a00-0000-fcd4-c0894b0c0000 pid=3147 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=1fc53af7-1a00-0000-fcd4-c0894b0c0000 pid=3147 execve guuid=af4f7cf9-1a00-0000-fcd4-c089520c0000 pid=3154 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=af4f7cf9-1a00-0000-fcd4-c089520c0000 pid=3154 execve guuid=d570c3fc-1a00-0000-fcd4-c089590c0000 pid=3161 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=d570c3fc-1a00-0000-fcd4-c089590c0000 pid=3161 execve guuid=d80c16fd-1a00-0000-fcd4-c0895b0c0000 pid=3163 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=d80c16fd-1a00-0000-fcd4-c0895b0c0000 pid=3163 execve guuid=9a355bfd-1a00-0000-fcd4-c0895d0c0000 pid=3165 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=9a355bfd-1a00-0000-fcd4-c0895d0c0000 pid=3165 clone guuid=24257dfd-1a00-0000-fcd4-c0895f0c0000 pid=3167 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=24257dfd-1a00-0000-fcd4-c0895f0c0000 pid=3167 execve guuid=3ffd43ff-1a00-0000-fcd4-c089660c0000 pid=3174 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=3ffd43ff-1a00-0000-fcd4-c089660c0000 pid=3174 execve guuid=7b2a7b02-1b00-0000-fcd4-c089700c0000 pid=3184 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7b2a7b02-1b00-0000-fcd4-c089700c0000 pid=3184 execve guuid=7b6ee102-1b00-0000-fcd4-c089730c0000 pid=3187 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7b6ee102-1b00-0000-fcd4-c089730c0000 pid=3187 execve guuid=f9f42c03-1b00-0000-fcd4-c089740c0000 pid=3188 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=f9f42c03-1b00-0000-fcd4-c089740c0000 pid=3188 clone guuid=71f06a03-1b00-0000-fcd4-c089760c0000 pid=3190 /usr/bin/wget net send-data guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=71f06a03-1b00-0000-fcd4-c089760c0000 pid=3190 execve guuid=7710f105-1b00-0000-fcd4-c0897d0c0000 pid=3197 /usr/bin/curl net send-data write-file guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=7710f105-1b00-0000-fcd4-c0897d0c0000 pid=3197 execve guuid=be64500b-1b00-0000-fcd4-c089890c0000 pid=3209 /usr/bin/cat guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=be64500b-1b00-0000-fcd4-c089890c0000 pid=3209 execve guuid=0f7ab90b-1b00-0000-fcd4-c0898b0c0000 pid=3211 /usr/bin/chmod guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=0f7ab90b-1b00-0000-fcd4-c0898b0c0000 pid=3211 execve guuid=aa96100c-1b00-0000-fcd4-c0898d0c0000 pid=3213 /usr/bin/bash guuid=f49b229d-1a00-0000-fcd4-c0896c0b0000 pid=2924->guuid=aa96100c-1b00-0000-fcd4-c0898d0c0000 pid=3213 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=e98f239e-1a00-0000-fcd4-c0896f0b0000 pid=2927->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=7f8e01a3-1a00-0000-fcd4-c089780b0000 pid=2936->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=94d848ad-1a00-0000-fcd4-c0898a0b0000 pid=2954->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=9db38aaf-1a00-0000-fcd4-c089900b0000 pid=2960->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=f0a0ccb7-1a00-0000-fcd4-c089970b0000 pid=2967->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=7d9d08bb-1a00-0000-fcd4-c089a00b0000 pid=2976->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=40f2d1bf-1a00-0000-fcd4-c089a50b0000 pid=2981->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=267ef7c1-1a00-0000-fcd4-c089a90b0000 pid=2985->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=546f7bc5-1a00-0000-fcd4-c089b50b0000 pid=2997->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=5b15afc7-1a00-0000-fcd4-c089bd0b0000 pid=3005->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=2a37fccb-1a00-0000-fcd4-c089ca0b0000 pid=3018->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=137573ce-1a00-0000-fcd4-c089ce0b0000 pid=3022->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=55b13ad4-1a00-0000-fcd4-c089dd0b0000 pid=3037->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=f74fe6d5-1a00-0000-fcd4-c089e20b0000 pid=3042->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=d892a6d9-1a00-0000-fcd4-c089f20b0000 pid=3058->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=2cb864db-1a00-0000-fcd4-c089f80b0000 pid=3064->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=2da1aedf-1a00-0000-fcd4-c089060c0000 pid=3078->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=fa1374e2-1a00-0000-fcd4-c0890e0c0000 pid=3086->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=b0aaf4ef-1a00-0000-fcd4-c089340c0000 pid=3124->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=707f46f2-1a00-0000-fcd4-c0893b0c0000 pid=3131->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=1fc53af7-1a00-0000-fcd4-c0894b0c0000 pid=3147->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=af4f7cf9-1a00-0000-fcd4-c089520c0000 pid=3154->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=24257dfd-1a00-0000-fcd4-c0895f0c0000 pid=3167->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=3ffd43ff-1a00-0000-fcd4-c089660c0000 pid=3174->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=71f06a03-1b00-0000-fcd4-c089760c0000 pid=3190->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=7710f105-1b00-0000-fcd4-c0897d0c0000 pid=3197->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:02:26 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 18ebc3f3e74fc7a11f097eefd4f5864a7a49b490449dc6adf37fbe86ba279427

(this sample)

  
Delivery method
Distributed via web download

Comments